Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

81–90 of 512 posts

Re: Twilio incident: What Signal users need to know

#81
post #53

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

Why are server-side contact lists needed to support identities not linked to phone numbers?

Re: Twilio incident: What Signal users need to know

#82

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

I think they are. I just also think the problem is a lot harder than people give it credit for. If they just go with a standard username (as in some form of a database lookup) then I'll be upset. But I'll be upset because this effectively doesn't solve any issue, and introduces others that have big privacy impacts and requires Signal to be a trusted source (which is antithetical to Signal's proposed mission).

I do wish Signal would be more transparent though. Given that this is such a difficult problem and they've been struggling with it for years, it reasons that it is time to seek help. This is like when a student just studies for hours and hours on end, spinning their wheels. They aren't learning anything. At some point you need a tutor, help from a friend, or asking the professor for help. (Or analogy in work if that's better)

Signal, it is time to be transparent.

Re: Twilio incident: What Signal users need to know

#83
post #34

Earlier quoted context omitted.

The sane alternative is that it could keep a client-side contact book that users would be responsible for managing entirely on their own, including when setting the app up on a new phone. Addendum: also, there is nothing preventing this type of contact book data from being backed-up/synced to a new phone, like any other data and settings of any other app. iOS has this feature since like 7 years now. Android, too, I'm…

That's a good way to build a secure messaging app nobody ever uses.

That anonymous IDs can be _optional_, in addition to phone numbers. Again, like Threema is already doing.

Re: Twilio incident: What Signal users need to know

#84
post #53

Earlier quoted context omitted.

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

Do "normies" care about high quality encryption? And did signal ever turn on username support?

I think developers have a moral responsibility to make their products as secure as possible, within reason and while still being usable. It doesn't matter if the users care about the benefits. To your second question: no, not yet.

Re: Twilio incident: What Signal users need to know

#85
This incident points to something much more severe. What role was this employee(s) whose credentials were compromised? How did these credentials allow even an employee to get plain text auth codes being sent out to end users? Such a permission should be extremely limited in who it is granted to.

Re: Twilio incident: What Signal users need to know

#86
post #65

Earlier quoted context omitted.

Users having to add their contacts each time they set Signal up on a new phone, should the app keep its own client-side contact book, doesn't sound like hassle. Could you please explain how Signal does not have a social network map, when 1) user accounts are equal to mobile phone numbers, and 2) Signal servers route messages between user accounts.

The Signal protocol has had "sealed sender" since 2018 - Signal server does not know who sent a message, because the sender's identity is E2E encrypted along with the message. Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.

Every inbound message is authenticated, and credentials are stored somewhere. Correct me if I am wrong, but I'm betting that it's with the same credential/channel as for logging-in a user (aka "sender").

Also, wasn't "sealed sender" broken (again) earlier this year by a group of researchers?

Re: Twilio incident: What Signal users need to know

#87

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

It's the easiest anti-spam measure, because it makes it expensive enough that spammers won't have a million accounts. Fake account detection is effectively put on the back of mobile carriers

Re: Twilio incident: What Signal users need to know

#88

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Less spam. A phone number is a much better deterrent against opening a hundred accounts than let’s say an email address.

Re: Twilio incident: What Signal users need to know

#89
post #55

Earlier quoted context omitted.

Signals very explicit goal is making something that's usable for everybody. If they'd wanted to make a nerd-messenger they'd make a different product. (I still consider it a major downside that the phone number is the only lookup key)

Sounds pretty drastic to me to draw the line between "everybody" and "nerds" at the point of the contact book being available or not.

Feel free to insert your word choice of "smartphone-flipping demographic" instead. The point is that if you argue based on "the crowd that goes for signal", that crowd being everyone is the clear aim of Signal, and thus they design around that goal.

Re: Twilio incident: What Signal users need to know

#90
post #8

Earlier quoted context omitted.

How do you deal with spam without requiring a phone number to register?

Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.

No post body was provided.
Post reply on HN